Re: KINK issue list
Michael Thomas <[email protected]> Fri, 04 Feb 2005 15:09:35 -0800
| Newsgroups | gmane.ietf.kink |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
On Mon, 2005-01-31 at 17:54, Kazunori Miyazawa wrote: > Hello, > > I have read the mails and I think these issues could be closed. > > Kamada-san described the checksum calculation and verification in > this mail. > http://www.vpnc.org/ietf-kink/mail-archive/msg00336.html > > If KINK adopts this, check sum length in KINK header will be two > octets because kcrypto specifies that the output of get_mic is > no longer than 65535 octets in the section 4. Yes, there is an inconsistency in the draft in this regard... the diagram which shows it as being one octet actually more closely reflects reality (unfortunately). I haven't thought very hard about how to resolve this. > BTW, if there are no strong reason, I like to move the check sum > field from the header to the end of message, because we could > be easy to access KINK_AP_REQ/REP payload and forget it after > verification. Am I understanding you as saying that you'd like this to not be in the KINK header at all? And instead be, like, in one of the payloads following the header? That might be problematic given the KINK_ENCRYPT payload and some other odd things that might surface. Mike
signature.asc
(application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iQCVAwUAQgQAr7MsDAj/Eq++AQJHRAP/dzhp2mpsQ49m1ZvYhtcAWJi55SCTolK6 YuqACrlwy6YCdIRmaKAAz6gpimhj9ILv73OE0jyH/+AzbhNmYWYb4rsTUc3TnnEo f39LL42Z0AGOg5BV4OYqQqMqeg5rMSry0A2HVsTpwBc0mb/41xqpOEZfj2JuAKhv WU9277q1uO0= =liqr -----END PGP SIGNATURE-----